GHSA-46r5-59fg-2fjc
Dashboard / Vulnerabilities / GHSA-46r5-59fg-2fjc
Summary: Deserialization of Untrusted Data in Infinispan
Details: It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-15089, https://github.com/infinispan/infinispan/pull/5639, https://github.com/infinispan/infinispan/commit/1deadcb1c74ea0337abd5382c0150b000f6b106f, https://github.com/infinispan/infinispan/commit/2944b0d1369a230bde88392b222921537c99331e, https://access.redhat.com/errata/RHSA-2018:0294, https://access.redhat.com/errata/RHSA-2018:0478, https://access.redhat.com/errata/RHSA-2018:0479, https://access.redhat.com/errata/RHSA-2018:0480, https://access.redhat.com/errata/RHSA-2018:0481, https://access.redhat.com/errata/RHSA-2018:0501, https://access.redhat.com/errata/RHSA-2019:1326, https://github.com/infinispan/infinispan
Affected packages
Package
Name: org.infinispan:infinispan-core
Purl: pkg:maven/org.infinispan/infinispan-core
Affected ranges
Type: ECOSYSTEM
Events:
